SIM Resource Booking
Cloud-based platform for managing bookings, asset tracking, and access control. SIM Resource Booking combines resource reservations with asset lifecycle management—tracking equipment location, maintenance, and utilisation alongside room and workspace bookings. Automated safety inductions, permissions, and comprehensive reporting. Used by schools, NHS sites, and councils to manage resources and assets efficiently.
Features
- Book shared resources: rooms, desks, labs, studios, equipment
- Works on phone, tablet and desktop (no app required)
- Integrated payments for chargeable bookings or events
- Subscription and membership management (e.g. hot desk passes)
- Public or private event booking with attendee limits and waitlists
- Safety inductions and access steps for equipment or spaces
- Asset lifecycle management, tracking, maintenance and depreciation
- Live calendar, availability search and location filtering
- Exportable reports: bookings, payments, audit trails, usage
- Barcode/QR code asset identification and check-in/check-out
Benefits
- One system to manage space, resources, users and payments
- Ideal for NHS, councils, schools, libraries, labs and venues
- Automates booking rules and approvals by user role or group
- Enables safe access with induction tracking and entry control
- Supports community access, room hire and events with payments
- Subscription features for co-working, sports, or shared spaces
- Public and staff bookings on any device, no install needed
- Reduce equipment loss through systematic tracking
- Flexible for training, public engagement, hybrid work or overflow
- Integrated booking and asset management in one system
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 5 8 9 5 3 9 3 8 7 3 9 0 5 4
Contact
BOUNCE AGENCY LIMITED
Andrew Downie
Telephone: 02074917401
Email: admin@bounce-agency.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Our service is delivered via public cloud and accessed through web browsers (Chrome, Edge, Safari, Firefox). A stable internet connection is required. No installation or plug-ins are needed. Planned maintenance is scheduled outside UK business hours with at least 5 working days’ notice. Emergency maintenance is rare but may occur with shorter notice if necessary to address critical issues. The system is designed for desktop, tablet and mobile browsers; however, certain complex admin features are best managed on larger screens. SMS notifications are optional and require access to user phone numbers. Integration support may be required for legacy booking systems.
- System requirements
-
- Stable internet connection
- Modern browser: Chrome, Edge, Safari or Firefox.
- JavaScript and cookies must be enabled.
- Smartphone with camera for barcode/QR asset scanning (optional)
- Email access for notifications
- SMS-enabled mobile for alerts
- Desktop or tablet for admin users
- No additional licences or plug-ins needed
- Secure HTTPS access enabled on network
- Compatible with public sector firewalls and configurations
User support
- Email or online ticketing support
- Yes
- Support response times
-
We respond to all support queries within 4 working hours during standard service hours (Monday–Friday, 09:00–17:00 UK time).
Response time commitments:
- Critical issues: 4 hours (multiple users or core functionality affected)
- High priority: 4 hours (individual users or specific features)
- Medium priority: 8 hours (minor issues with workarounds)
- Low priority: Next working day (enhancement requests, general queries)
Weekend and out-of-hours:
Queries received outside standard hours, including weekends and public holidays, are responded to by 10:00 on the next working day. Emergency support available by arrangement for critical contracts.
Response times measured from query submission. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
We have conducted thorough testing of our web chat interface using multiple assistive technologies to ensure accessibility for all users.
Testing methods included:
- Screen readers: NVDA (Windows), JAWS (Windows), VoiceOver (macOS/iOS)
- Keyboard-only navigation without mouse input
- High-contrast modes (Windows High Contrast, browser extensions)
- Screen magnification software (ZoomText, Windows Magnifier)
- Voice control and speech recognition (Dragon NaturallySpeaking)
Testing was carried out by team members trained in assistive technology use, simulating real-world user scenarios including:
- Initiating chat sessions
- Reading and responding to messages
- Navigating chat history
- Accessing pre-chat forms
- Using emoji and attachments
- Managing notifications
- Closing and reopening conversations
Key accessibility features validated:
- All chat functions accessible via keyboard (Tab, Enter, Escape, Arrow keys)
- Screen reader announcements for new messages
- Clear focus indicators on interactive elements
- Sufficient colour contrast (4.5:1 minimum)
- Alternative text for visual elements
- ARIA live regions for dynamic message updates
- Logical tab order through interface
We have documented remaining limitations and maintain an accessibility roadmap. Testing occurs with each interface update to maintain WCAG 2.2 AA compliance. Our approach ensures inclusive support access for all users. - Onsite support
- Yes
- Support levels
-
We provide a single inclusive support level suitable for public sector organisations of all sizes. This includes access to our online ticketing system, email support, and telephone assistance during standard service hours (Monday to Friday, 09:00–17:00 UK time). All queries receive a response within 4 working hours.
Emergency or out-of-hours support can be arranged for contracts requiring critical coverage. Each customer is assigned a named support contact for continuity and familiarity.
Onboarding support is included as standard, covering account setup, permissions, branding, workspace configuration, and initial user training.
For clients requiring enhanced technical guidance, a dedicated Technical Account Manager (TAM) or Cloud Support Engineer can be provided for:
- Onboarding and implementation support
- Performance reviews and optimisation
- Integration planning and API guidance
- Custom development consultation
- Quarterly business reviews
This is available as a separate costed service, typically from £650/day depending on scope and duration.
We use a transparent support ticketing system, allowing users to set issue priority and monitor ticket status. Support performance is reviewed quarterly with enterprise customers to drive service improvements.
Our support model is designed to be clear, accountable, and tailored to the operational needs of NHS, education, and local authority users. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Standard implementation takes 3 weeks from order to go-live. When a buyer adopts SIM Resource Booking, we deliver a structured onboarding process tailored to their operational and technical environment. It begins with a discovery session to define venue types, resource categories, asset types, user permissions, booking policies, and safety workflows. We configure the system accordingly, applying templates where appropriate and customising access controls to meet buyer needs.
We support integration with existing CRM systems (e.g. Microsoft Dynamics, Salesforce, or custom databases), ensuring booking activity, user access, and engagement data sync seamlessly into the buyer's digital ecosystem. We handle integration via secure API endpoints, with technical support throughout.
Live onboarding includes remote training for admins, coordinators and users, supported by downloadable guides, walkthrough videos, and a dedicated knowledge hub. We also offer onsite training for large or complex deployments.
Calendar integrations (e.g. Outlook, Google, ICS) and optional SSO setup are completed during onboarding. For buyers using kiosks or tablets for self-service booking, we provide UI configuration and access management.
A named onboarding lead ensures smooth delivery and handover. Post-launch, we offer a 30-day bedding-in period with enhanced support. This guarantees every buyer achieves a confident, fully-aligned rollout delivering immediate operational value. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At contract end, users can extract all data securely via the admin dashboard or request a full export from our support team.
Data included in exports:
- Booking records (past, present, and future reservations)
- Asset registers and inventory records
- Equipment maintenance history and service logs
- Asset transfer and location history
- User accounts and permissions
- Audit logs and activity trails
- Documents and attachments
- System configurations and custom settings
- Payment and transaction records (if applicable)
- Induction completion records
- Reports and analytics data
Export options:
Data is provided in open, non-proprietary formats including CSV, JSON, XML, and PDF to support onward use or migration to alternative systems. Exports can be filtered by date range, location, or department.
Security and support:
All exports are encrypted in transit (TLS 1.2+) and access-controlled via role-based permissions. We provide clear step-by-step guidance, export templates, and data dictionaries to ensure safe and complete data extraction.
There is no additional charge for standard end-of-contract data exports. Dedicated support is available throughout the process to assist the buyer's IT team. We can schedule exports outside business hours to minimize operational impact. - End-of-contract process
-
At contract end, users are notified in advance and provided with a clear offboarding plan. All client data can be exported in open, non-proprietary formats (CSV, JSON, PDF) via the admin interface or with assistance from our support team. This includes booking records, user profiles, audit logs, documents, and configuration data. Standard data export and support are included in the contract price at no additional cost.
We provide read-only access to the system for up to 30 days post-contract, giving clients time to complete data extraction or handover. After this period, accounts are deactivated, and data is securely deleted in line with our ISO 27001–compliant data destruction policy.
Where required, optional paid services are available, including:
• Bespoke data transformation or formatting
• Extended access beyond 30 days
• Formal decommissioning reports
• Workshops to document workflows developed during the contract
• Technical consultancy for data migration to a new system
All post-contract services are quoted in advance and delivered in collaboration with the buyer’s technical team. Our goal is to ensure a smooth, secure, and compliant transition with no disruption to venue operations or service continuity. We align offboarding with NCSC guidance and government cloud security principles. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is fully responsive and accessible via mobile browsers without loss of core functionality. Interfaces are optimised for smaller screens, touch navigation, and reduced bandwidth environments. Some complex admin features (e.g., asset configuration, bulk operations) are streamlined for mobile, but all critical tasks—including resource booking, availability search, asset tracking, and dashboard views—are available on both mobile and desktop.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Our service includes a secure, browser-based interface with role-based access, supporting all major desktop and mobile web browsers. The interface features:
- Intuitive dashboard with real-time booking and asset status
- Drag-and-drop calendar for easy scheduling
- Visual floor plans for space selection
- Search and filter tools for resources and assets
- Quick-access booking forms and check-in/check-out
- Mobile-optimised touch interface
- Customisable widgets per user role
- In-app notifications and alerts
- Responsive design adapting to screen size
- Dark mode for accessibility
No software installation required. Users access via standard HTTPS connection with single sign-on (SSO) support. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We have conducted comprehensive manual and automated interface testing using tools such as Axe, WAVE, and Lighthouse to assess compatibility with screen readers (e.g. NVDA, JAWS, VoiceOver) and keyboard-only navigation.
Key user journeys tested for accessibility include:
- Making and modifying bookings
- Checking availability and searching resources
- Managing assets and maintenance records
- Navigating dashboards and reports
- Completing check-in/check-out processes
- Accessing help documentation
- Submitting support requests
We engaged users with visual impairments in structured testing sessions to validate:
- Colour contrast ratios (minimum 4.5:1 for text)
- Focus states and keyboard navigation order
- Alternative text for images and icons
- Screen reader announcements for dynamic content
- Form field labels and error messages
- Button and link descriptions
- Heading structure and landmark regions
Testing revealed and we addressed:
- Improved focus indicators on interactive elements
- Enhanced ARIA labels for complex components
- Optimised tab order for logical flow
- Added skip navigation links
- Ensured all functionality available via keyboard
Accessibility refinements were made in line with WCAG 2.2 AA standards. We conduct ongoing testing with each major release and maintain an accessibility statement detailing conformance status. - API
- Yes
- What users can and can't do using the API
-
Our secure RESTful API allows authorised users to integrate SIM Resource Booking into third-party systems or automate workspace/resource management tasks.
What users can do:
• Create, update, and cancel workspace/resource bookings
• Query availability across locations or asset types
• Manage users, permissions, and group memberships
• Retrieve booking data for reporting or audit
• Configure alerts and sync bookings with calendars (e.g. Outlook, Google)
How users set up/make changes:
• API keys and authentication tokens are issued during onboarding
• Users can configure endpoints, filters, and data payloads via the API
• Admin users can automate onboarding or manage resources dynamically
Limitations:
• Some admin functions (e.g. billing setup, branding) are only available via the web interface
• API access is role-based and rate-limited (2000 requests/hour)
• Certain audit-level data and internal logs are restricted for security
• Create, update, and track assets (equipment, devices, vehicles)
• Record maintenance activities and service history
• Query asset location, status, and assignment
• Generate asset reports and depreciation schedules
Full API documentation is available in HTML and PDF formats and includes endpoint descriptions, usage examples, error codes, and setup guidance. An API sandbox is available for test integration. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise core elements of the service to suit operational needs.
What can be customised:
- Asset categories, types, and custom fields
- Maintenance schedules and service templates
- Location hierarchies and transfer workflows
- Asset status definitions and lifecycle stages
- Depreciation methods and replacement thresholds
- Booking rules and approval workflows
- User roles and permission levels
- Notification preferences and alert templates
- Branding (logo, colour palette, email templates)
- Resource categories and booking time slots
- Pricing structures for paid bookings
- Report templates and dashboard layouts
- Induction steps and safety requirements
- Calendar integration settings (Outlook, Google)
How users can customise:
- Via the system settings panel for authorised administrators
- Through onboarding workshops with our support team
- Using API endpoints for integrations and automation
- Through bulk import tools for large-scale configuration
Who can customise:
- Buyers with administrative access
- Third-party integrators approved by the buyer
- Our support team, on request, for advanced configuration
All customisations are preserved through system updates. Changes are version-controlled and can be rolled back if needed. Customisation changes are logged in audit trails for compliance.
Scaling
- Independence of resources
- We guarantee user independence through a multi-tenant cloud architecture hosted on AWS UK regions. Each customer environment has logically isolated application containers, separate databases, and individual encryption keys. Compute and storage resources automatically scale based on individual demand, ensuring no performance degradation due to other users. Network traffic is prioritised per customer, with real-time monitoring and throttling to prevent resource contention. Role-based access controls and data partitioning ensure that users can only access their own data and resources. This design ensures consistent performance, data isolation, and security—regardless of concurrent usage by other organisations on the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide a full suite of real-time metrics via the admin dashboard and exportable reports. Metrics include: bookings (by space, time, user), utilisation rates, cancellations, no-shows, user activity, induction completions, asset tracking (location, status, transfers), maintenance schedules and completion, equipment lifecycle and depreciation, system uptime, and access logs. Reports filter by date, resource type, location, or asset category. All data exports in CSV or JSON for integration with CRMs or BI tools. Custom reporting available. Metrics support operational insight, performance optimisation, asset management, compliance monitoring, and strategic decision-making.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can securely export all data through the admin interface or API. Exports include workspace bookings, asset inventory records, equipment maintenance logs, asset location history, user records, space/resource configurations, safety induction data, activity logs, and audit trails. Data can be filtered by date, location, or asset, and downloaded in CSV, JSON, or PDF formats. Exports are encrypted in transit and access logged for compliance. Admins can schedule recurring exports or request support-assisted data extraction. API-based exports support integration with third-party systems such as CRMs or reporting tools. Documentation and guidance ensure safe, accurate export. All data extraction capabilities are included.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- JSON
- PDF/A
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- JSON
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% availability of the SIM Resource Booking platform, measured monthly. This equates to a maximum allowable downtime of approximately 43 minutes per month. Our service level agreement (SLA) includes proactive monitoring, rapid incident response, and robust failover systems to ensure high resilience.
If availability falls below the guaranteed threshold in any given month (excluding scheduled maintenance windows, force majeure, or customer-induced issues), users will be eligible for service credits as follows:
• 99.0% – 99.89%: 5% service credit
• 95.0% – 98.99%: 10% service credit
• Below 95.0%: up to 50% service credit
Service credits are calculated as a percentage of that month’s fee and can be applied as a credit against future invoices. Customers can request a service credit by raising a support ticket within 10 business days of the affected month.
We host on AWS UK regions, which offer enterprise-grade resilience, availability zones, and real-time failover. All updates are deployed using zero-downtime deployment processes, and customers are notified of any planned maintenance in advance.
We continuously monitor uptime through automated dashboards and alerting systems, and reports are available on request or through the client portal. - Approach to resilience
-
Our service is designed with resilience and continuity at its core. We host the SIM Resource Booking platform on AWS UK-based cloud infrastructure, which provides multiple layers of redundancy and failover across Availability Zones (AZs). These physically separate AZs are interconnected via low-latency links and enable us to distribute compute, storage, and database resources to eliminate single points of failure.
The service automatically scales to meet demand and reroutes traffic in the event of infrastructure failure. We use AWS services with built-in resilience, such as Amazon RDS (multi-AZ deployments), S3 (99.999999999% durability), and EC2 with auto-healing groups. Data is continuously replicated across secure zones and backed up regularly.
We implement automated monitoring, alerting, and failover processes to detect and respond to incidents in real-time. Disaster recovery procedures are tested regularly, and we can restore full functionality within a pre-agreed Recovery Time Objective (RTO) and Recovery Point Objective (RPO), guaranteed under 4 hours and 15 minutes, respectively.
All resilience design decisions align with the UK Government’s Cloud Security Principles, including asset protection and business continuity.
Full details of our infrastructure resilience design and disaster recovery processes are available on request to eligible buyers. - Outage reporting
-
We notify users of outages through multiple integrated channels to ensure prompt visibility and trust. Primary notifications are issued via automated email alerts to registered technical contacts and administrators. These alerts are sent immediately when any service degradation, partial outage or full outage is detected and include initial diagnostics, impact assessment and estimated time to resolution if available.
We maintain a dedicated, customer-accessible service status dashboard, which is updated in real time. This dashboard provides detailed, transparent information on current system status, components affected, incident history, and planned maintenance windows. It also allows users to subscribe to specific updates based on their role or system usage.
For enterprise buyers or integrators, we offer an optional status API, enabling integration of our service health information into your own dashboards or monitoring tools, and facilitating real-time automated polling of service status.
Following any outage, we publish incident summaries outlining cause, resolution steps, and mitigation measures. These are available through the dashboard and upon request.
Our outage reporting processes are designed to meet the needs of both operational and strategic stakeholders, support incident response planning, and ensure a high degree of transparency and accountability across all service tiers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly role-based and limited to authorised personnel only. We enforce Multi-Factor Authentication (MFA) for all administrative accounts and restrict access by IP where appropriate. User roles are defined by the principle of least privilege, with audit logs tracking all administrative actions. Support channels are segregated from production environments and access is logged and reviewed regularly. Sensitive data shared via support is encrypted in transit and at rest. Changes made via management interfaces are tracked through version-controlled logs, and suspicious access attempts trigger automated alerts for investigation.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- Our service is hosted on AWS, which complies with ISO 27017, ISO 27018, SOC 2, and PCI DSS. We hold Cyber Essentials certification. We follow NCSC Cloud Security Principles, apply secure-by-design practices, including threat modelling, access control, and regular audits to ensure robust governance across development, deployment, and service operations.
- Information security policies and processes
-
We follow a robust, risk-based information security management approach aligned to ISO/IEC 27001 principles. Our policies cover data protection, access control, encryption, secure software development, incident management, and business continuity.
All staff are trained on our information security policies at induction and through regular refresher sessions. Staff responsibilities are clearly defined in our Acceptable Use Policy and reinforced by contractual obligations and NDAs.
We operate a “secure by design” development approach, including regular vulnerability assessments, penetration testing, and adherence to NCSC Cloud Security Principles. Multi-factor authentication, least-privilege access, and encrypted data storage are enforced across all systems.
Security responsibilities are owned by the senior leadership team, with oversight from the Managing Director. A designated Security Lead manages policy compliance, incident response and risk reviews. Regular internal audits are conducted, and policy breaches are escalated to senior management immediately for investigation and remediation.
Incident response processes follow a structured approach: detection, triage, containment, eradication, recovery, and lessons learned. Serious breaches are reported to affected parties and regulators where applicable.
Security policies are reviewed quarterly or in response to major changes in threat landscape or service operations. Documentation is version controlled and securely stored with access logging. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We operate a robust configuration and change management process aligned with ISO/IEC 27001 and CSA CCM v4.0. All service components are tracked throughout their lifecycle using a secure configuration management system. Change requests are logged, impact-assessed, security-reviewed, tested, and documented in line with government’s Operational Security principle. Every change is evaluated for risks to availability, confidentiality, and integrity. Approved changes are version-controlled and deployed using automated pipelines. Emergency changes are logged, reviewed retrospectively, and fully audited. The entire process ensures minimal service disruption, maintains secure service continuity, and supports traceability, with comprehensive records retained for audit and compliance purposes.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We follow a proactive vulnerability management process aligned to ISO/IEC 27001 and CSA CCM v4.0. Threats are identified through automated vulnerability scanning tools, threat intelligence feeds (including NCSC advisories), and vendor alerts. All vulnerabilities are risk assessed based on severity, exploitability, and service impact. Critical patches are deployed within 24 hours; high-severity issues within 72 hours; all others within a defined patching window. We monitor emerging threats daily and implement continuous security updates via DevSecOps practices. Vulnerability reports and mitigation actions are logged and reviewed monthly by our security team to ensure accountability and continuous improvement.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use real-time monitoring and automated alerting systems (AWS CloudWatch, GuardDuty) to detect potential compromises, anomalous behaviour and unauthorised access attempts. All logs are centralised and continuously analysed against known threat patterns. On identifying a potential compromise, our security team initiates our documented incident response protocol within 15 minutes. This includes triage, impact assessment, isolation of affected systems, and root cause analysis. High-priority incidents are escalated immediately to senior engineers and, if necessary, to the customer. We maintain detailed audit trails and generate post-incident reports. Our monitoring and response procedures align with CSA CCM v4.0 and ISO/IEC 27001 standards.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We maintain pre-defined incident management processes for common events, including data breaches, service disruptions, and unauthorised access attempts. Users can report incidents via our online ticketing system, dedicated support email, or phone. All incidents are logged, triaged, and prioritised based on severity and impact. We follow defined escalation paths to ensure rapid response and resolution, including root cause analysis. Post-incident reports are shared with affected users and include a timeline, actions taken, and mitigation strategies. We maintain detailed incident logs for auditability and continual improvement, and align our processes with ISO/IEC 27035:2011 best practices.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer a free 14-day trial of SIM Resource Booking with access to core features: workspace booking, asset tracking, team access, safety inductions, and admin tools. Excludes integrations (e.g. CRM, calendar sync) and payment setup. Trial access is set up manually and includes onboarding support. Extensions available on request.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 8%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fccc8a9f-bf9c-4a21-a6d3-31bdfe3e82df
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- AWS ISO/IEC 27017:2015 – Cloud Security Controls
- AWS ISO/IEC 27018:2019 – Protection of Personal Data
- AWS SOC 1 / SOC 2 / SOC 3 reports
- AWS CSA STAR Level 2 certification
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-